# How to logstash patterns/regex/co

**URL:** <https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819>\
**Category:** Logstash\
**Created:** [May 15, 2020, 12:33pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819 "2020-05-15T12:33:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ELK212](https://avatars.discourse-cdn.com/v4/letter/e/3bc359/32.png) [@ELK212](https://discuss.elastic.co/u/ELK212)\
**Post date:** [May 15, 2020, 12:33pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/1 "2020-05-15T12:33:23Z")

</div>

Hello,

I'm just playing around with logstash and hope to get help with a few topics.

I'm trying to log some HP Procurve Switch syslog messages into elasticsearch. I used the example filter from the website. Which looks the following:  
`match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }`

The part **%{DATA:syslog\_program}** logs the program which this message is coming from.

My switch sends the following message for example:  
`May 15 14:04:23 192.168.1.254 00179 mgr: SME SSH from 192.168.1.22 - MANAGER Mode`

**1)** I get the following output on commandline:

```auto
    {
         "syslog_hostname" => "192.168.1.254",
             "received_at" => "2020-05-15T12:04:23.500Z",
              "@timestamp" => 2020-05-15T12:04:23.000Z,
          "syslog_message" => " SME SSH from 192.168.1.254 - MANAGER Mode",
                 "message" => "<46> May 15 14:04:23 192.168.1.254 00179 mgr: SME SSH from 192.168.1.22 - MANAGER Mode",
        "syslog_timestamp" => "May 15 14:04:23",
                "facility" => 0,
                "@version" => "1",
                "severity" => 0,
                    "host" => "10.46.12.51",
                    "type" => "syslog",
          "syslog_program" => "00179 mgr",
           "received_from" => "192.168.1.254 ",
                "priority" => 0,
                    "tags" => [
            [0] "_grokparsefailure_sysloginput"
        ],
          "facility_label" => "kernel",
          "severity_label" => "Emergency"
    }

```

Why is there a \_grokparsefailure\_sysloginput? What is the cause for that? How can I interpret this?

**2)** As you can see also there is a number leading the syslog program. Don't know if this is RFC compliant coming from the switch. I tried to write a regex to exclude this number, because I don't need this and want to have it cleaner.

I tried it with the following regex which works in online regex testers but not with logstash:  
`\D+\:\s{2}`

So my pattern file looks like:  
`HPPROGRAM \D+\:\s{2}`

And my filter:

```auto
    filter {
      if [type] == "syslog" {
        grok {
          patterns_dir => ["/etc/logstash/patterns"]
          match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{HPPROGRAM :syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
          add_field => ["received_at", "%{@timestamp}"]
          add_field => ["received_from", "%{host}"]
        }
        date {
          match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
        }
      }
    }

```

But it simply isn't working with the following error:  
[0] "\_grokparsefailure\_sysloginput",  
[1] "\_grokparsefailure"

Isn't it right that my regex should match the program string if I want to extraxt the program string?! I'm really confused.

**3)** Where are the default patterns stored?  
**4)** How can I use regex match groups?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 15, 2020, 1:24pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/2 "2020-05-15T13:24:43Z")

</div>

can you post what final mapping do you expect?

> [@ELK212](#):
>
> %{DATA:syslog\_program}

this portion maps `syslog_program` to `00179 mgr` because DATA equals to .\*?

you can find grok patterns [here](https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns)

---

<div class="post-metadata">

**Author:** ![ELK212](https://avatars.discourse-cdn.com/v4/letter/e/3bc359/32.png) [@ELK212](https://discuss.elastic.co/u/ELK212)\
**Post date:** [May 15, 2020, 1:40pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/3 "2020-05-15T13:40:16Z")

</div>

I only want the "mgr" (or any other string which sends my switch) without the number.

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 15, 2020, 1:51pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/4 "2020-05-15T13:51:16Z")

</div>

`match => { "message" => “ %{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{INT} %{WORD:syslog_program}: %{GREEDYDATA:syslog-message} “`

drop INT if you don’t want it or replace it with \d+

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 15, 2020, 3:14pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/5 "2020-05-15T15:14:44Z")

</div>

> [@ELK212](#):
>
> Why is there a \_grokparsefailure\_sysloginput?

The syslog input applies a grok\_pattern, which by [default](https://github.com/logstash-plugins/logstash-input-syslog/blob/f162ada0d8ea87ce54362e1e613796ab641f0669/lib/logstash/inputs/syslog.rb#L45) parses off the PRI at the beginning (the number in angle brackets). If that grok fails then it adds that tag.

---

<div class="post-metadata">

**Author:** ![ELK212](https://avatars.discourse-cdn.com/v4/letter/e/3bc359/32.png) [@ELK212](https://discuss.elastic.co/u/ELK212)\
**Post date:** [May 19, 2020, 3:08pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/6 "2020-05-19T15:08:16Z")

</div>

PRI stands for?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 19, 2020, 3:28pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/7 "2020-05-19T15:28:29Z")

</div>

> [@ELK212](#):
>
> PRI stands for?

Priority. RFC 3164 [defines](https://tools.ietf.org/html/rfc3164#section-4.1.1) it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2020, 3:28pm UTC](https://discuss.elastic.co/t/how-to-logstash-patterns-regex-co/232819/8 "2020-06-16T15:28:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
